LWN.net Logo

SELinux and security patches for 2.6.28

From:  James Morris <jmorris@namei.org>
To:  Linus Torvalds <torvalds@linux-foundation.org>
Subject:  [GIT] SELinux and security patches for 2.6.28
Date:  Fri, 10 Oct 2008 11:32:52 +1100 (EST)
Message-ID:  <alpine.LRH.1.10.0810101131290.27355@tundra.namei.org>
Cc:  linux-security-module@vger.kernel.org
Archive-link:  Article, Thread

Hi Linus,

Please pull the following patches for 2.6.28.

The following changes since commit 3fa8749e584b55f1180411ab1b51117190bac1e5:
  Linus Torvalds (1):
        Linux 2.6.27

are available in the git repository at:

  git://git.kernel.org/pub/scm/linux/kernel/git/jmorris/security-testing-2.6 for-linus

Adrian Bunk (1):
      make selinux_write_opts() static

Casey Schaufler (1):
      smack: limit privilege by label

David Howells (1):
      SELinux: Fix a potentially uninitialised variable in SELinux hooks

Eric Paris (1):
      securityfs: do not depend on CONFIG_SECURITY

James Morris (4):
      Merge branch 'master' into next
      SELinux: add gitignore file for mdp script
      Merge branch 'master' into next
      Merge branch 'next' into for-linus

KaiGai Kohei (1):
      SELinux: add boundary support and thread context assignment

Paul Moore (1):
      selinux: Fix an uninitialized variable BUG/panic in selinux_secattr_to_sid()

Randy Dunlap (1):
      security: add/fix security kernel-doc

Serge E. Hallyn (2):
      selinux: add support for installing a dummy policy (v2)
      file capabilities: uninline cap_safe_nice

Stephen Smalley (2):
      Update selinux info in MAINTAINERS and Kconfig help text
      selinux: use default proc sid on symlinks

Vesa-Matti J Kari (2):
      SELinux: Trivial minor fixes that change C null character style
      SELinux: trivial, remove unneeded local variable

Vesa-Matti Kari (2):
      selinux: conditional expression type validation was off-by-one
      selinux: Unify for- and while-loop style

 Documentation/DocBook/kernel-api.tmpl |    1 +
 Documentation/SELinux.txt             |   27 ++++
 MAINTAINERS                           |    5 +-
 drivers/char/tpm/Kconfig              |    1 +
 include/linux/security.h              |   54 ++++----
 scripts/Makefile                      |    3 +-
 scripts/selinux/Makefile              |    2 +
 scripts/selinux/README                |    2 +
 scripts/selinux/install_policy.sh     |   69 ++++++++++
 scripts/selinux/mdp/.gitignore        |    2 +
 scripts/selinux/mdp/Makefile          |    5 +
 scripts/selinux/mdp/dbus_contexts     |    6 +
 scripts/selinux/mdp/mdp.c             |  242 +++++++++++++++++++++++++++++++++
 security/Kconfig                      |    8 +
 security/Makefile                     |    3 +-
 security/commoncap.c                  |    2 +-
 security/inode.c                      |   33 ++---
 security/security.c                   |    8 +-
 security/selinux/Kconfig              |    3 -
 security/selinux/avc.c                |    2 +-
 security/selinux/hooks.c              |   62 ++++++---
 security/selinux/include/avc.h        |    4 +
 security/selinux/include/security.h   |   15 ++-
 security/selinux/ss/avtab.c           |    8 +-
 security/selinux/ss/conditional.c     |   18 ++--
 security/selinux/ss/conditional.h     |    2 +-
 security/selinux/ss/ebitmap.c         |    4 +-
 security/selinux/ss/hashtab.c         |    6 +-
 security/selinux/ss/mls.c             |   14 +-
 security/selinux/ss/policydb.c        |  225 +++++++++++++++++++++++++++----
 security/selinux/ss/policydb.h        |    5 +
 security/selinux/ss/services.c        |  180 ++++++++++++++++++++++++-
 security/selinux/ss/sidtab.c          |   12 +-
 security/smack/smack.h                |    1 +
 security/smack/smack_access.c         |   10 ++-
 security/smack/smackfs.c              |   92 +++++++++++++
 36 files changed, 995 insertions(+), 141 deletions(-)
 create mode 100644 Documentation/SELinux.txt
 create mode 100644 scripts/selinux/Makefile
 create mode 100644 scripts/selinux/README
 create mode 100644 scripts/selinux/install_policy.sh
 create mode 100644 scripts/selinux/mdp/.gitignore
 create mode 100644 scripts/selinux/mdp/Makefile
 create mode 100644 scripts/selinux/mdp/dbus_contexts
 create mode 100644 scripts/selinux/mdp/mdp.c
--
To unsubscribe from this list: send the line "unsubscribe linux-security-module" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html


Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds